VORANT. Threat Intelligence Sign in Get the full feed

PluXml CMS versions 5.8.21 and 5.9.0-rc7 contain three vulnerabilities

high vulnerability

PluXml CMS versions 5.8.21 and 5.9.0-rc7 contain three vulnerabilities: stored XSS via SVG upload, stored XSS in static pages, and session fixation enabling account hijacking.

CERT Polska coordinated disclosure of three vulnerabilities affecting PluXml CMS, a content management system. CVE-2026-24350 is a stored cross-site scripting vulnerability in the file upload functionality that allows authenticated attackers to upload malicious SVG files. When victims interact with the uploaded file, arbitrary JavaScript executes in their browser context. CVE-2026-24351 is another stored XSS flaw in the static pages editing feature, enabling attackers with editing privileges to inject malicious HTML and JavaScript that executes when users visit the compromised page.

CVE-2026-24352 is a session fixation vulnerability where the application assigns session identifiers before authentication and fails to regenerate them post-login. This allows attackers to set a known session ID for victims and subsequently hijack their authenticated sessions. CERT Polska confirmed vulnerabilities in versions 5.8.21 and 5.9.0-rc7 through testing, though the vendor did not provide information on the full range of affected versions. The disclosure was responsibly reported by security researcher Arkadiusz Marta.

Organizations using PluXml CMS should assess their exposure and monitor for vendor patches. The combination of XSS and session fixation vulnerabilities could enable attackers to compromise user accounts and inject persistent malicious content into websites running the affected CMS.

Mentioned in this report

Vulnerabilities CVE-2026-24350CVE-2026-24351CVE-2026-24352

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-24350

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free